@hadleybeeman @davidbaron @w3ctag Did y'all figure out what you'll be recommending relating to `[SecureContext]`? github.com/w3ctag/design-pri… :)
1
1
Thanks for the reminder. I wrote down a strawman proposal to (hopefully) lead to further discussion: github.com/w3ctag/design-pri…
1
It's a good start, thanks for getting the conversation going. My hope is that we can end up with something more aggressive. :)
1
1
More aggressive in what respects?
1
I'd like to see secure context restrictions as the default stance, with non-secure exposure discouraged and requiring justification.
1
1
I think I did take that position on defaults, conditional on the new thing being a visibly distinct feature. Could write on justification...

Aug 23, 2017 · 8:39 PM UTC

2
"All new APIs should be restricted to secure contexts." would be a stronger intro. :)
1
1
And "When deciding whether a feature should be limited to secure contexts..." positions the restriction as an opt-in needing justification.